All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Taylor, Grant" <gtaylor@riverviewtech.net>
To: netfilter@lists.netfilter.org
Subject: Re: matching the first packet of a connection
Date: Wed, 04 May 2005 16:36:47 -0500	[thread overview]
Message-ID: <4279406F.1030703@riverviewtech.net> (raw)
In-Reply-To: <1115241663.5410.18.camel@porky>

> In the scope of the NuFW project we need to queue SYN packets for
> connection we want to authenticate (see http://www.nufw.org/ for details
> on principles). For a single connection we want to QUEUE only the first
> packet coming to the firewall (SYN packet in the case of TCP). All
> subsequent packets of the connection even if they are also SYN packet
> (if for example server is unreachable or does not exist) have to me
> authorized or drop depending of the decision taken on the first packet.
> In fact this is an extension of the ESTABLISHED or RELATED match.

I'm not quite sure how to "queue" packets as take them in to some sort of FIFO with a pause but possibly you do and you just need help matching which packets to queue.  I know with the recent match extension you could probably ""remember a connection attempt (how to remember for just that connection is a question in and of it's self though (working on this)) and queue the first one and then take some sort of action on subsequent based on how the packets are dequeued.  I think you are going to need to rely on some sort of external input, possibly via the condition match extension.  I've seen and briefly read about NuFU but I need to do so again to get up to speed to help with this.  Let me go do some reading and I'll get back to you.



Grant. . . .


  reply	other threads:[~2005-05-04 21:36 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-05-04 15:21 matching the first packet of a connection Eric Leblond
2005-05-04 17:43 ` George Alexandru Dragoi
2005-05-04 18:50   ` Eric Leblond
2005-05-04 17:57 ` Thomas Jones
2005-05-04 18:11   ` Daniel Lopes
2005-05-04 18:34     ` Jason Opperisano
2005-05-04 19:37 ` Taylor, Grant
2005-05-04 21:21   ` Eric Leblond
2005-05-04 21:36     ` Taylor, Grant [this message]
2005-05-05  7:53     ` Taylor, Grant
2005-05-04 21:30   ` Eric Leblond

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4279406F.1030703@riverviewtech.net \
    --to=gtaylor@riverviewtech.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.